VYPR
Critical severity9.8NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026

CVE-2016-10192

CVE-2016-10192

Description

Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.

Affected products

14
  • FFmpeg/Ffmpeg14 versions
    cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*range: <=2.8.9
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ffmpeg:ffmpeg:3.2.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.